ZeroHour

CVE-2021-3979

CVSS 3.1
6.5 medium
EPSS
<1%p45
Published
()
Modified
Description

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Vendors
redhatfedoraproject
Products
ceph storage, openshift container storage, openshift data foundation, openstack platform, ceph storage for ibm z systems, ceph storage for power, fedora
Weakness
CWE-327, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.